CVE-2026-107299Medium· 5.9▾ Sunlitmsgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
msgpack5 < 6.1.0Patched in:
msgpack5 6.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107302High· 7.5msgpack5 is a msgpack v5 implementation for node.js and the browser
CVE-2026-107300High· 7.5msgpack5 is a msgpack v5 implementation for node.js and the browser
CVE-2026-107301Medium· 6.5msgpack5 is a msgpack v5 implementation for node.js and the browser
CVE-2026-107297Medium· 5.9msgpack5 is a msgpack v5 implementation for node.js and the browser
CVE-2026-107298Medium· 5.3msgpack5 is a msgpack v5 implementation for node.js and the browser
CVE-2026-107296Low· 3.7msgpack5 is a msgpack v5 implementation for node.js and the browser